Packages changed: ImageMagick MozillaFirefox (156.0 -> 157.0.1) akonadi (26.08.1 -> 26.08.2) akonadi-calendar (26.08.1 -> 26.08.2) akonadi-calendar-tools (26.08.1 -> 26.08.2) akonadi-contacts (26.08.1 -> 26.08.2) akonadi-import-wizard (26.08.1 -> 26.08.2) akonadi-mime (26.08.1 -> 26.08.2) akonadi-search (26.08.1 -> 26.08.2) akregator (26.08.1 -> 26.08.2) appstream-glib ark (26.08.1 -> 26.08.2) baloo-widgets (26.08.1 -> 26.08.2) calendarsupport (26.08.1 -> 26.08.2) cyrus-sasl dolphin (26.08.1 -> 26.08.2) dracut (112+suse.53.g97cbf62 -> 112+suse.54.g5c7a104) eventviews (26.08.1 -> 26.08.2) expat (2.8.5 -> 2.9.0) ffmpeg-8 ffmpegthumbs (26.08.1 -> 26.08.2) glib2 (2.88.3 -> 2.88.4) gnome-control-center gnome-settings-daemon gnome-shell grantleetheme (26.08.1 -> 26.08.2) gstreamer (1.28.7 -> 1.28.8) gstreamer-devtools (1.28.7 -> 1.28.8) gstreamer-plugins-bad (1.28.7 -> 1.28.8) gstreamer-plugins-base (1.28.7 -> 1.28.8) gstreamer-plugins-good (1.28.7 -> 1.28.8) gstreamer-plugins-libav (1.28.7 -> 1.28.8) gstreamer-plugins-rs (1.28.7 -> 1.28.8) gstreamer-plugins-ugly (1.28.7 -> 1.28.8) incidenceeditor (26.08.1 -> 26.08.2) kaccounts-integration (26.08.1 -> 26.08.2) kaccounts-providers (26.08.1 -> 26.08.2) kaddressbook (26.08.1 -> 26.08.2) kamera (26.08.1 -> 26.08.2) kate (26.08.1 -> 26.08.2) kcalc (26.08.1 -> 26.08.2) kcalutils (26.08.1 -> 26.08.2) kcharselect (26.08.1 -> 26.08.2) kcolorchooser (26.08.1 -> 26.08.2) kdegraphics-mobipocket (26.08.1 -> 26.08.2) kdegraphics-thumbnailers (26.08.1 -> 26.08.2) kdenetwork-filesharing (26.08.1 -> 26.08.2) kdepim-addons (26.08.1 -> 26.08.2) kdepim-runtime (26.08.1 -> 26.08.2) kdialog (26.08.1 -> 26.08.2) khelpcenter (26.08.1 -> 26.08.2) kidentitymanagement (26.08.1 -> 26.08.2) kimap (26.08.1 -> 26.08.2) kio-extras (26.08.1 -> 26.08.2) kio_audiocd (26.08.1 -> 26.08.2) kitinerary (26.08.1 -> 26.08.2) kldap (26.08.1 -> 26.08.2) kleopatra (26.08.1 -> 26.08.2) kmag (26.08.1 -> 26.08.2) kmail (26.08.1 -> 26.08.2) kmail-account-wizard (26.08.1 -> 26.08.2) kmailtransport (26.08.1 -> 26.08.2) kmbox (26.08.1 -> 26.08.2) kmousetool (26.08.1 -> 26.08.2) kompare (26.08.1 -> 26.08.2) konsole (26.08.1 -> 26.08.2) kontact (26.08.1 -> 26.08.2) kontactinterface (26.08.1 -> 26.08.2) konversation (26.08.1 -> 26.08.2) korganizer (26.08.1 -> 26.08.2) kpimtextedit (26.08.1 -> 26.08.2) kpkpass (26.08.1 -> 26.08.2) ksanecore (26.08.1 -> 26.08.2) ksmtp (26.08.1 -> 26.08.2) ktnef (26.08.1 -> 26.08.2) kwalletmanager (26.08.1 -> 26.08.2) libeconf (0.8.4 -> 0.8.5) libgravatar (26.08.1 -> 26.08.2) libkcddb-qt6 (26.08.1 -> 26.08.2) libkdcraw (26.08.1 -> 26.08.2) libkdepim (26.08.1 -> 26.08.2) libkexiv2-qt6 (26.08.1 -> 26.08.2) libkgapi6 (26.08.1 -> 26.08.2) libkleo (26.08.1 -> 26.08.2) libkomparediff2 (26.08.1 -> 26.08.2) libksane (26.08.1 -> 26.08.2) libksieve (26.08.1 -> 26.08.2) mailcommon (26.08.1 -> 26.08.2) mailimporter (26.08.1 -> 26.08.2) messagelib (26.08.1 -> 26.08.2) mimetreeparser (26.08.1 -> 26.08.2) okular (26.08.1 -> 26.08.2) open-iscsi openSUSE-release (20261009 -> 20261010) parted pimcommon (26.08.1 -> 26.08.2) pipewire python-dnspython (2.8.0 -> 2.9.0) qrca (26.08.1 -> 26.08.2) signon-kwallet-extension (26.08.1 -> 26.08.2) skanlite (26.08.1 -> 26.08.2) vlc webkitgtk3 webkitgtk4 wireplumber xorg-x11-server xwayland === Details === ==== ImageMagick ==== Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - Ensure the different src.rpm have different names. ==== MozillaFirefox ==== Version update (156.0 -> 157.0.1) Subpackages: MozillaFirefox-branding-upstream MozillaFirefox-translations-common - Mozilla Firefox 157.0.1 * Fixed downloads failing on macOS when Firefox is set to ask where to save files but doesn't have permission to access the Downloads folder. (bmo#2077390) * Fixed the sidebar getting stuck on the Bookmarks or AI Chatbot panel for some users. (bmo#2076296) * Fixed the Restore from Backup option not appearing during onboarding on Windows. (bmo#2073401) MFSA 2026-104 * CVE-2026-106016 (bmo#2067465) Mitigation bypass in the File Handling component - Mozilla Firefox 157.0 https://www.firefox.com/en-US/firefox/157.0/releasenotes/ MFSA 2026-97 (bsc#1282929) * CVE-2026-100756 (bmo#2047721) Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-100757 (bmo#2049352) Use-after-free in the Widget component * CVE-2026-100758 (bmo#2049792) Sandbox escape in the DOM: Navigation component * CVE-2026-100759 (bmo#2054736) Uninitialized memory in the Storage: Quota Manager component * CVE-2026-100760 (bmo#2058017) Sandbox escape in the Security: Process Sandboxing component * CVE-2026-100761 (bmo#2059020) Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-100762 (bmo#2059404) Sandbox escape due to use-after-free in the DOM: Content Processes component * CVE-2026-100763 (bmo#2059929) Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-100764 (bmo#2061290) Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-100765 (bmo#2061399) Use-after-free in the JavaScript: WebAssembly component * CVE-2026-100766 (bmo#2061526) Information disclosure in the Networking: JAR component * CVE-2026-100767 (bmo#2063680) Use-after-free in the Networking: Cache component * CVE-2026-100768 (bmo#2064832) Use-after-free in the Graphics: WebGPU component * CVE-2026-100769 (bmo#2067190) Use-after-free in the JavaScript: WebAssembly component * CVE-2026-100770 (bmo#2068322) Sandbox escape due to use-after-free in the DOM: Content Processes component * CVE-2026-100771 (bmo#2068336) Undefined behavior in the DOM: Streams component * CVE-2026-100772 (bmo#2068340) Use-after-free in the DOM: Core & HTML component * CVE-2026-100773 (bmo#2068346) Use-after-free in the Storage: IndexedDB component * CVE-2026-100774 (bmo#2068351) Use-after-free in the DOM: Core & HTML component * CVE-2026-100775 (bmo#2068367) Sandbox escape in the Graphics component * CVE-2026-100776 (bmo#2068374) Use-after-free in the JavaScript: WebAssembly component * CVE-2026-100777 (bmo#2068375) Use-after-free in the Graphics: Canvas2D component * CVE-2026-100778 (bmo#2068406) Sandbox escape due to use-after-free in the DOM: Core & HTML component * CVE-2026-100779 (bmo#2068417) Use-after-free in the XSLT component * CVE-2026-100780 (bmo#2068422) Use-after-free in the DOM: Core & HTML component * CVE-2026-100781 (bmo#2068434) Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component * CVE-2026-100782 (bmo#2068456) Privilege escalation due to incorrect boundary conditions in the Graphics component * CVE-2026-100783 (bmo#2069804) Uninitialized memory in the Audio/Video component * CVE-2026-100784 (bmo#2070264) Use-after-free in the Layout: Text and Fonts component * CVE-2026-100785 (bmo#2071064) Use-after-free in the DOM: Core & HTML component * CVE-2026-100786 (bmo#2071067) Sandbox escape due to use-after-free in the Graphics component * CVE-2026-100787 (bmo#2071068) Sandbox escape in the XUL component * CVE-2026-100788 (bmo#2072413) Invalid pointer in the JavaScript: WebAssembly component * CVE-2026-100789 (bmo#2072429) Use-after-free in the Graphics: Canvas2D component * CVE-2026-100790 (bmo#2072432) Use-after-free in the XSLT component * CVE-2026-100791 (bmo#2072433) Use-after-free in the DOM: Core & HTML component * CVE-2026-100792 (bmo#2073266) JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-100793 (bmo#2073268) JIT miscompilation in the JavaScript Engine component * CVE-2026-100794 (bmo#2028871) Sandbox escape due to incorrect boundary conditions in the ... changelog too long, skipping 82 lines ... - requires NSS >= 3.129 ==== akonadi ==== Version update (26.08.1 -> 26.08.2) Subpackages: akonadi-lang libKPim6AkonadiAgentBase6 libKPim6AkonadiAgentWidgetBase6 libKPim6AkonadiCore6 libKPim6AkonadiPrivate6 libKPim6AkonadiWidgets6 libKPim6AkonadiXml6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * ETM: mark re-added ancestor collections as populated - Stop requiring mariadb and qt6-sql-mysql ==== akonadi-calendar ==== Version update (26.08.1 -> 26.08.2) Subpackages: akonadi-plugin-calendar kalendarac libKPim6AkonadiCalendar6 libKPim6AkonadiCalendar6-lang libKPim6AkonadiCalendarCore6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== akonadi-calendar-tools ==== Version update (26.08.1 -> 26.08.2) Subpackages: akonadi-calendar-tools-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== akonadi-contacts ==== Version update (26.08.1 -> 26.08.2) Subpackages: akonadi-contacts-lang akonadi-plugin-contacts libKPim6AkonadiContactCore6 libKPim6AkonadiContactWidgets6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== akonadi-import-wizard ==== Version update (26.08.1 -> 26.08.2) Subpackages: akonadi-import-wizard-lang libKPim6ImportWizard6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== akonadi-mime ==== Version update (26.08.1 -> 26.08.2) Subpackages: akonadi-plugin-mime libKPim6AkonadiMime6 libKPim6AkonadiMime6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== akonadi-search ==== Version update (26.08.1 -> 26.08.2) Subpackages: akonadi-search-lang libKPim6AkonadiSearch6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== akregator ==== Version update (26.08.1 -> 26.08.2) Subpackages: akregator-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== appstream-glib ==== Subpackages: appstream-glib-lang libappstream-glib8 - Update version dependencies according to meson.build. ==== ark ==== Version update (26.08.1 -> 26.08.2) Subpackages: ark-lang libkerfuffle26 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== baloo-widgets ==== Version update (26.08.1 -> 26.08.2) Subpackages: baloo-widgets-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== calendarsupport ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6CalendarSupport6 libKPim6CalendarSupport6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== cyrus-sasl ==== Subpackages: cyrus-sasl-crammd5 cyrus-sasl-digestmd5 cyrus-sasl-gssapi cyrus-sasl-plain libsasl2-3 libsasl2-3-32bit - Fix heap-based buffer overflow in DIGEST-MD5 add_to_challenge(): buffer size was not recomputed after quoting expanded the value, allowing a malicious server to overflow the client heap. (bsc#1284687) CVE-2026-107161 * add cyrus-sasl-digestmd5-quote-overflow.patch - Clean up an synchronize changes - Fix packages for Immutable Mode - cyrus-sasl (jsc#PED-14856) ==== dolphin ==== Version update (26.08.1 -> 26.08.2) Subpackages: dolphin-part dolphin-part-lang libdolphinvcs6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * CI: Comment flatpak job * confirmationssettingspage: Set vertical text alignment for form labels * kstandarditemlistwidget: Fix poorly legible selection text with certain styles and color schemes (kde#524851) * folderspanel: set hightLightEntireRow for view (kde#486383) * dolphinview: Refresh the default zoom level when previews are toggled (kde#524842) * viewproperties: keep the style chosen for a special folder (kde#501442) ==== dracut ==== Version update (112+suse.53.g97cbf62 -> 112+suse.54.g5c7a104) - Update to version 112+suse.54.g5c7a104: * fix(systemd-pcrextend): add systemd-pcrextend.socket ==== eventviews ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6EventViews6 libKPim6EventViews6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== expat ==== Version update (2.8.5 -> 2.9.0) Subpackages: libexpat1 - update to 2.9.0: * Security fixes: * CVE-2026-102633, bsc#1283493: integer overflow in expat_realloc on 32bit platforms * CVE-2026-77214, bsc#1284334: out-of-bounds read in XML_ParseBuffer due to missing validation of the len parameter * drop the patch, fixed upstream: * expat-CVE-2026-102633.patch * Bug fixes: * Handle OOM when copying encodingName in XML_ParserReset * New features: * Properties API to get and set scalar properties of a parser * Five new 64bit location API functions ==== ffmpeg-8 ==== Subpackages: libavcodec62 libavfilter11 libavformat62 libavutil60 libswresample6 libswscale9 - Correctly enable apv encoder, encoder is named liboapv. ==== ffmpegthumbs ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== glib2 ==== Version update (2.88.3 -> 2.88.4) Subpackages: glib2-lang glib2-tools libgio-2_0-0 libgirepository-2_0-0 libglib-2_0-0 libglib-2_0-0-32bit libgmodule-2_0-0 libgobject-2_0-0 libgthread-2_0-0 typelib-1_0-GIRepository-3_0 typelib-1_0-GLib-2_0 typelib-1_0-GLibUnix-2_0 typelib-1_0-GModule-2_0 typelib-1_0-GObject-2_0 typelib-1_0-Gio-2_0 - Update to version 2.88.4: * Bugs fixed: + gio/tests/services: - Installed service file contains build path - Fix installed service file containing build path + docs: Fix gio gi-docgen docs_url + gconstructor: Reference _tls_used also on GCC, CLang + fix: handle long filenames in trash by truncating from front + Backport various security fixes * Updated translations. ==== gnome-control-center ==== Subpackages: gnome-control-center-color gnome-control-center-goa gnome-control-center-lang gnome-control-center-user-faces gnome-control-center-users - Add libgnome-volume-control-Avoid-NULL-deref.patch: Avoid NULL deref when card has no active profile (bsc#1278300 glgo#GNOME/libgnome-volume-control!38) ==== gnome-settings-daemon ==== Subpackages: gnome-settings-daemon-lang - Add libgnome-volume-control-Avoid-NULL-deref.patch: Avoid NULL deref when card has no active profile (bsc#1278300 glgo#GNOME/libgnome-volume-control!38) ==== gnome-shell ==== Subpackages: gnome-extensions gnome-shell-calendar gnome-shell-lang - Add libgnome-volume-control-Avoid-NULL-deref.patch: Avoid NULL deref when card has no active profile (bsc#1278300 glgo#GNOME/libgnome-volume-control!38) ==== grantleetheme ==== Version update (26.08.1 -> 26.08.2) Subpackages: grantleetheme-lang libKPim6GrantleeTheme6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== gstreamer ==== Version update (1.28.7 -> 1.28.8) Subpackages: gstreamer-lang gstreamer-utils libgstreamer-1_0-0 typelib-1_0-Gst-1_0 - Update to version 1.28.8: * Highlighted bugfixes: + Various security fixes and playback fixes + Fix adaptivedemux2 HLS and DASH playback regression + Fix FLAC audio seeking regression + Various RTP depayloader and RTSP client SDP handling fixes + MXF demuxer: Added support for reading AAF AIFF-AIFC audio + VA-API compositor: Fix alpha blending with Intel driver + Windows media audio/video seeking improvements + AMD AMF AV1 video encoder force-keyframe fixes + Fix endless drain in some FFmpeg wrapper audio encoders and support dual mono hlssink3 improvements + ISOBMFF dash/iso/fmp4 muxer fixes for timestamp rollover in 2036 + cerbero: Rework checksum verification to allow mirror retries + Various bug fixes, build fixes, memory leak fixes, and other stability and reliability improvements * gstreamer: + baseparse: Fix accumulating of detection buffers + buffer: Don't leave buffers with dangling memory pointers if appending memory fails + buffer: Prevent NULL pointer dereferences when deserializing reference timestamp meta + value: fix crash when comparing mixed-type lists + ptp: Fix build failures with Rust 1.99 - Rebase gstreamer-pie.patch with quilt. - Migrate to xz compression and manual service run. ==== gstreamer-devtools ==== Version update (1.28.7 -> 1.28.8) - Update to version 1.28.8: * No changes, stable bump only. - Migrate to xz compression and manual service run ==== gstreamer-plugins-bad ==== Version update (1.28.7 -> 1.28.8) Subpackages: gstreamer-plugins-bad-lang libgstadaptivedemux-1_0-0 libgstanalytics-1_0-0 libgstbadaudio-1_0-0 libgstbasecamerabinsrc-1_0-0 libgstcodecparsers-1_0-0 libgstcodecs-1_0-0 libgstcuda-1_0-0 libgsthip-1_0-0 libgstinsertbin-1_0-0 libgstisoff-1_0-0 libgstmpegts-1_0-0 libgstmse-1_0-0 libgstphotography-1_0-0 libgstplay-1_0-0 libgstsctp-1_0-0 libgsturidownloader-1_0-0 libgstva-1_0-0 libgstvulkan-1_0-0 libgstwayland-1_0-0 libgstwebrtc-1_0-0 libgstwebrtcnice-1_0-0 - Update to version 1.28.8: * adpcmenc: stop the IMA encode loop before reading past the input frame * amfav1enc: Force a key frame on force-key-unit * ccutils: Miscellaneous parsing fixes * closedcaption: Use truncated length when converting CEA708 / CEA608 S334-1A data too * d3d12: Various GstBaseTransform::transform_meta() related fixes * hipevent: Fix device ID getter * hipmemory: Fix minor leak and typo * jpegparse: handle missing NUL terminator in COM segment * mpegts: fix GError usage in a loop * mxfdemux: Add support for reading AAF AIFF-AIFC audio * mxfmux: Fix possible crash when adding a new segment due to frame reordering * nvh264dec: Fix top field POC in DPB entry * rsvgdec: Fix out-of-bounds read when scanning for SVG end tag * rtp: Various small (RTP and not) depayloader fixes * segmentationoverlay: + Fix off-by-one bug and add test + Respect video meta strides * va: compositor: Fix alpha blending with Intel driver * vmaf: use GST_PARAM_DOC_SHOW_DEFAULT for "threads" property * vulkan: + encoder: DPB slots and DBP barrier fixes + h26x enc/dec misc fixes + tests: examples fixes * webrtc/nice: Fix crash in nice_candidate_free during gather - Refresh spandsp3.patch with quilt. - Migrate to xz compression and manual service run ==== gstreamer-plugins-base ==== Version update (1.28.7 -> 1.28.8) Subpackages: gstreamer-plugins-base-lang libgstallocators-1_0-0 libgstapp-1_0-0 libgstaudio-1_0-0 libgstfft-1_0-0 libgstgl-1_0-0 libgstpbutils-1_0-0 libgstriff-1_0-0 libgstrtp-1_0-0 libgstrtsp-1_0-0 libgstsdp-1_0-0 libgsttag-1_0-0 libgstvideo-1_0-0 typelib-1_0-GstAudio-1_0 typelib-1_0-GstPbutils-1_0 typelib-1_0-GstTag-1_0 typelib-1_0-GstVideo-1_0 - Update to version 1.28.8: * appsink: Reset EOS state on PAUSED → READY * audio-resampler-neon: handle Thumb1-only builds correctly * audio-resampler-neon: Follow-up from "fix Thumb encoding and use Clang O2 calculation for strides" * audio: video: Validate audio/video meta deserialization & other meta deserialization fixes * audioconverter: guard against NULL input in do_convert_out * sdpmessage: Avoid sign bit when hex-escaping chars * udmabuf: Open device with O_RDONLY instead O_RDWR * videoconvertscale: Take GstVideoMeta into account when converting - Rebase patches with quilt. - Migrate to xz compression and manual service run. - Drop required versions define, manually set it, as the obs ignores the define. ==== gstreamer-plugins-good ==== Version update (1.28.7 -> 1.28.8) Subpackages: gstreamer-plugins-good-gtk gstreamer-plugins-good-lang - Update to version 1.28.8: * adaptivedemux2: + Drain downloadhelper main context with the main context as the thread default + SIGABRT in downloadhelper_stop() draining transfer context + Remove redundant hls_dep fallback, re-enabling unit tests * audiofx: Miscellaneous FIR filter fixes * flacparse: + regression since 1.28 - valid FLAC errors out with "Internal data stream error" after a seek + Fix resyncing after a seek * matroska: Use the display unit for storing the display aspect ratio more accurately * matroskamux: DisplayWidth rounding loses aspect ratio for non-integer PARs * matroskademux: fix crash caused by bogus xiph codec data packet sizes * qtmux: preserve earliest reordered presentation time * rtph265depay: Check for short packets before processing them * rtph265pay: unmap the RTP header before appending the payload * rtpsession: Ignore SDES priv RTCP packets with invalid lengths * rtp: Various small (RTP and not) depayloader fixes * rtpL8depay, rtpL16depay, rtpL24depay: fix out of bounds write for high channel count * rtspsrc: + Fix handling of missing control attribute with multiple media sections + SIGSEGV in gst_rtspsrc_setup_streams_start() when an SDP media section has no a=control attribute * v4l2: + fix guint overflow in calculate_max_sizeimage + object: Don't corrupt the caller's filter caps when probing - Migrate to xz compression and manual service run ==== gstreamer-plugins-libav ==== Version update (1.28.7 -> 1.28.8) - Update to version 1.28.8: * avaudenc: Fix endless drain of encoders that support flushing * avcodecmap: Take the dual mono case into account * avenc_tta: Allow up to 16 channels and use that in the 16 channel test * Disable OMX encoders and decoders - Update version dependencies according to meson.build - Drop leftover doc subpackage from spec, not built for many years - Migrate to xz compression and manual service run ==== gstreamer-plugins-rs ==== Version update (1.28.7 -> 1.28.8) - Update to version 1.28.8: * fmp4mux: Fix racy test_large_gop_split_at_fragment_boundary_chunked test * gifdec: + error out if a frameless GIF is somehow supplied + error out if a frameless GIF is somehow supplied, try 2 * HLS sink improvements * isobmff: Fix NTP seconds roll-over past 2036 * raptorq: Downgrade to 2.0.0 again * reqwesthttpsrc: Handle empty response chunks * rtspsrc2: Fix handling of scheme and parameter parsing * Reapply "Switch to aws-lc-rs" * Update dependencies * meson: Skip validate-plugins if gstreamer-validate-1.0 is missing - Update version dependencies according to meson.build. - Migrate to xz compression and manual service run ==== gstreamer-plugins-ugly ==== Version update (1.28.7 -> 1.28.8) Subpackages: gstreamer-plugins-ugly-lang - Update to version 1.28.8: * asfdemux: + Explicitly set packet to zero if seek_time is zero + Clamp simple index entry count against the available data size * rtpasfdepay: Ignore zero-length ASF packets - Migrate to xz compression and manual service run ==== incidenceeditor ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6IncidenceEditor6 libKPim6IncidenceEditor6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Fix LSAN failure in conflictresolvertest ==== kaccounts-integration ==== Version update (26.08.1 -> 26.08.2) Subpackages: kaccounts-integration-lang libkaccounts6-2 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * CI: Remove Qt5 build ==== kaccounts-providers ==== Version update (26.08.1 -> 26.08.2) Subpackages: kaccounts-providers-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kaddressbook ==== Version update (26.08.1 -> 26.08.2) Subpackages: kaddressbook-doc kaddressbook-lang libKPim6AddressbookImportExport6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kamera ==== Version update (26.08.1 -> 26.08.2) Subpackages: kio_kamera kio_kamera-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kate ==== Version update (26.08.1 -> 26.08.2) Subpackages: kate-lang kate-plugins - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * it makes no sense to detach if we are not in a terminal (kde#525600) ==== kcalc ==== Version update (26.08.1 -> 26.08.2) Subpackages: kcalc-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Use more KDE mirrors of GNU software * Use KDE mirror of MPFR to avoid reliability issues with GNU infrastructure ==== kcalutils ==== Version update (26.08.1 -> 26.08.2) Subpackages: kcalutils-lang libKPim6CalendarUtils6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kcharselect ==== Version update (26.08.1 -> 26.08.2) Subpackages: kcharselect-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kcolorchooser ==== Version update (26.08.1 -> 26.08.2) Subpackages: kcolorchooser-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kdegraphics-mobipocket ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kdegraphics-thumbnailers ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * gscreator: Return early if img allocation failed ==== kdenetwork-filesharing ==== Version update (26.08.1 -> 26.08.2) Subpackages: kdenetwork-filesharing-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kdepim-addons ==== Version update (26.08.1 -> 26.08.2) Subpackages: kdepim-addons-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Fix Qt 6.12 build ==== kdepim-runtime ==== Version update (26.08.1 -> 26.08.2) Subpackages: kdepim-runtime-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kdialog ==== Version update (26.08.1 -> 26.08.2) Subpackages: kdialog-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== khelpcenter ==== Version update (26.08.1 -> 26.08.2) Subpackages: khelpcenter-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kidentitymanagement ==== Version update (26.08.1 -> 26.08.2) Subpackages: kidentitymanagement-lang libKPim6IdentityManagementCore6 libKPim6IdentityManagementWidgets6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kimap ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6IMAP6 libKPim6IMAP6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kio-extras ==== Version update (26.08.1 -> 26.08.2) Subpackages: kio-extras-lang libkioarchive6-6 trash_kcm - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Thumbnail worker: fix unneeded scaling of folder pixmaps and sub thumbs ==== kio_audiocd ==== Version update (26.08.1 -> 26.08.2) Subpackages: kio_audiocd-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kitinerary ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6Itinerary6 libKPim6Itinerary6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Fix SBB QR code matching pattern to cover current Bern Tickets * Add Snållåget PDF ticket extractor script * Adapt Entur extractor to a new/alternative ticket PDF layout * Fix reading date values from JSON with Qt 6.13 * accor: Prefer checkin/out dates from JSON-LD data * feat: support Spanish bus tickets from ALSA * Add extractor for Delta Air Lines emails * Add extractor for Frontier Airlines emails * Support "English" Ouigo tickets ==== kldap ==== Version update (26.08.1 -> 26.08.2) Subpackages: kldap-lang libKPim6LdapCore6 libKPim6LdapWidgets6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kleopatra ==== Version update (26.08.1 -> 26.08.2) Subpackages: kleopatra-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kmag ==== Version update (26.08.1 -> 26.08.2) Subpackages: kmag-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kmail ==== Version update (26.08.1 -> 26.08.2) Subpackages: kmail-application-icons kmail-lang ktnef - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Fix mem leak here * Avoid mem leak in autotest. We need to get menu * Fix icon name: "emblem-information" not "emblem-informations" ==== kmail-account-wizard ==== Version update (26.08.1 -> 26.08.2) Subpackages: kmail-account-wizard-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kmailtransport ==== Version update (26.08.1 -> 26.08.2) Subpackages: kmailtransport-lang libKPim6MailTransport6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kmbox ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6Mbox6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kmousetool ==== Version update (26.08.1 -> 26.08.2) Subpackages: kmousetool-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kompare ==== Version update (26.08.1 -> 26.08.2) Subpackages: kompare-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== konsole ==== Version update (26.08.1 -> 26.08.2) Subpackages: konsole-part konsole-part-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Fix creation of graphics while scrolling ==== kontact ==== Version update (26.08.1 -> 26.08.2) Subpackages: kontact-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kontactinterface ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6KontactInterface6 libKPim6KontactInterface6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== konversation ==== Version update (26.08.1 -> 26.08.2) Subpackages: konversation-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== korganizer ==== Version update (26.08.1 -> 26.08.2) Subpackages: korganizer-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * cppcheck-suppressions.xml - suppress constParameterCallback ==== kpimtextedit ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6TextEdit6 libKPim6TextEdit6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kpkpass ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6PkPass6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== ksanecore ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKSaneCore6-1 libKSaneCore6-1-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== ksmtp ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6SMTP6 libKPim6SMTP6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== ktnef ==== Version update (26.08.1 -> 26.08.2) Subpackages: ktnef-debug-categories libKPim6Tnef6 libKPim6Tnef6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Fix reading MAPI string values lacking null termination (kde#525967) ==== kwalletmanager ==== Version update (26.08.1 -> 26.08.2) Subpackages: kwalletmanager-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * src/konfigurator: fix Tab focus (kde#526104) ==== libeconf ==== Version update (0.8.4 -> 0.8.5) Subpackages: libeconf0 libeconf0-32bit - Update to version 0.8.5: * Fix a crash if sections are empty (#249) ==== libgravatar ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6Gravatar6 libKPim6Gravatar6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libkcddb-qt6 ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKCddb5 libkcddb-qt6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Fix error signal connection ==== libkdcraw ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKDcrawQt6-5 libkdcraw-qt6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libkdepim ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6Libkdepim6 libkdepim-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libkexiv2-qt6 ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKExiv2Qt6-0 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libkgapi6 ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6GAPICalendar6 libKPim6GAPICore6 libKPim6GAPIPeople6 libKPim6GAPITasks6 libkgapi6-lang libkgapi6-sasl2-kdexoauth2 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libkleo ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6libkleo6 libkleo-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libkomparediff2 ==== Version update (26.08.1 -> 26.08.2) Subpackages: libkomparediff2-6 libkomparediff2-6-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libksane ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKSaneWidgets6 libksane-icons libksane-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libksieve ==== Version update (26.08.1 -> 26.08.2) Subpackages: libksieve-lang libksieve6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== mailcommon ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6MailCommon6 mailcommon-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== mailimporter ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6MailImporter6 libKPim6MailImporterAkonadi6 mailimporter-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== messagelib ==== Version update (26.08.1 -> 26.08.2) Subpackages: messagelib-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Update expected results for GpgME 2.2.0 and GnuPG 2.5.22 * Fix bug 525868: Kmail crashes when sending signed email (kde#525868) ==== mimetreeparser ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6MimeTreeParserCore6 libKPim6MimeTreeParserCore6-lang libKPim6MimeTreeParserWidgets6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== okular ==== Version update (26.08.1 -> 26.08.2) Subpackages: okular-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * JS: Ensure interval timers dont outlive the app * JS: Scope interval timer lifetime more narrow * JS: move interval timers to document scope * JS: move field cache to document scope * JS: Make all bridge-object cppowned * JS: Ensure global objects are c++ owned * JS: Ensure timers dont outlive the app * Wrap some pdf specific javascript console functions to console.log * Drop custom non-functioning console logger; just debug dump things * Memory-safety: Dont let raw pointers out * Small executeScriptEvent refactor * Check action is of type Script before static casting to it * Adapt to newer clang-format * add Arabic Percent Sign to parseZoomString() * Fix signature panel crash on document refresh (kde#525809) ==== open-iscsi ==== Subpackages: iscsiuio libopeniscsiusr0 - Update to version 2.1.13.suse+4.dc2446a1: * iscsid: honor REPORT LUNS DATA HAS CHANGED again (#557) * Convert shell scripts to POSIX sh (#552) * Preparing for version 2.1.13 * iscsiuio: fix incorrect comparison of IPv6 subnet mask * usr: verify IPC peer credentials before sending data * login: fix infinite redirect loops with configurable limits * iscsiuio: strengthen IPv6 payload length validation in uip_process() * iscsiuio: strengthen DHCPv6 option parsing loop bound check * iscsiuio: validate DHCPv6 IA_NA option lengths to prevent OOB reads * usr: network code ioctl handling improvements * fix typo in user-facing error message in verify_mode_params() (#548) * gitignore: ignore generated build artifacts (#550) * iscsiadm: handle getopt errors directly (#551) * Fix iscsi_conn_iface_has_ip error handling (#531) * Fix reopen log freq change (#542) * iscsi_net_util: fix broken VLAN support in find_vlan_dev (#545) * Fixes for CVEs CVE-2026-18724 - CVE-2026-18728 (#544) * usr: fix "-Wdiscarded-qualifiers" warning in auth.c (#539) * usr: Fix -Wdiscarded-qualifiers warning in iqn_name_valid (#537) * iscsiuio: Fix -Waddress-of-packed-member (#534) * Fixes CVEs: + bsc#1275171/CVE-2026-18724 + bsc#1275258/CVE-2026-18725 + bsc#1275260/CVE-2026-18726 + bsc#1275261/CVE-2026-18727 + bsc#1275262/CVE-2026-18728 ==== openSUSE-release ==== Version update (20261009 -> 20261010) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== parted ==== Subpackages: libparted-fs-resize0 libparted2 parted-lang - fix description ==== pimcommon ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6PimCommon6 libKPim6PimCommonAkonadi6 pimcommon-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== pipewire ==== Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-jack pipewire-lang pipewire-libjack-0_3 pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Add conditional aptx for Tumbleweed, libfreeaptx now awailable. ==== python-dnspython ==== Version update (2.8.0 -> 2.9.0) - Update to version 2.9.0 * dnspython dns.name.from_wire_parser() excessive CPU use A maliciously crafted DNS message may cause dns.name.from_wire_parser() to use excessive CPU for DNS name decompression. Applications which process untrusted DNS wire form messages with dnspython may be degraded or DoS'd by the extra CPU use required. * Fix GHSA-45c3-73f7-pv4m Decompression chain length is limited to 16. Prior to this change, a maliciously crafted DNS message could cause dns.name.from_wire_parser() to use excessive CPU for DNS name decompression. Applications which processed untrusted DNS wire form messages with dnspython could be degraded or DoS’d by the extra CPU use required. * Httpx2 has replaced httpx for HTTPS TCP connections. * The minimum supported Python version is now 3.11. * DNSSEC now supports ML-DSA-44, a post-quantum signature algorithm. * The NSEC3 Next Hashed Owner Name in presentation format is now decoded as base32hex (RFC 5155 Section 1.3, RFC 4648 Extended Hex Alphabet). The letters W, X, Y, and Z are not in that alphabet; they used to be accepted and silently decoded to a different owner name, so to_text of the result did not match the input. They are now rejected. * The NID and L64 node/locator ids in presentation format are now rejected when a group contains anything other than hex digits. A sign or underscore, which int() silently accepts, produced a record whose text form did not parse back the same way (RFC 6742). * Rdata of a known type in the generic \# syntax, such as an NS record in a zone file, no longer fails to parse when it contains a name under the origin. Its names are relativized as in the type’s own text form. * The SVCB and HTTPS ech parameter value must now be an ECHConfigList with a correct length prefix and at least 4 octets of content (RFC 9848, RFC 9849). The individual ECHConfig structures are not checked. * SVCB and HTTPS SvcParamKeys in presentation format, including those listed in mandatory, must now be spelled as RFC 9460 requires: 1-63 lowercase letters, digits, or hyphens. Uppercase keys such as ALPN and keys with underscores such as no_default_alpn are rejected. * SVCB and HTTPS presentation format parsing now follows the escaping rules of RFC 9460. SvcParamKeys may not contain escapes (e.g. \097lpn=h2), and in comma-separated values (alpn, docpath) only \, and \\ are valid escapes after character-string decoding (e.g. alpn="h2\\x" is rejected). * SVCB and HTTPS parameters whose value must not be empty (mandatory, alpn, port, ipv4hint, ech, ipv6hint) are now rejected when empty in text form (e.g. alpn="" or key1=""), in wire form, and in the Python API. Per RFC 9460, an omitted value is the same as an empty one. This also rejects an empty ech value, which RFC 9848 does not allow. * A relative $ORIGIN in a zone file is now relative to the current origin, as RFC 1035 requires. Previously records after it were silently dropped. * dns.zone.Zone.verify_digest() now makes the two RFC 8976 section 4 checks it was missing: a ZONEMD RR only verifies the zone if its serial matches the zone’s SOA serial (step 5.1), and a ZONEMD RR whose scheme and hash algorithm are shared with another ZONEMD RR in the RRset does not verify the zone at all (step 4). * dns.reversename.to_address() now rejects IPv6 reverse-map names without exactly 32 single-character labels, instead of padding missing nibbles or accepting multiple nibbles in a label. * A "transaction setup" callable may be specified when reading a zone from a file, a string, or an inbound zone transfer. It is called just after the transaction is created. A Transaction- Limiter setup is available to limit the size of the zone. * Name and rdata "to text" is now done with the to_styled_text() method, allowing much greater control over text output. Application code that uses to_text() continues to work as before, but any custom Rdata implementations need to be updated to support to_styled_text(). * The socket type parameter to socket.getaddrinfo used to be called "socktype2 in Python 2, but was renamed to "type" in Python 3. We applied this change on the python3 branch almost a decade ago, but it was lost in the "single code base, only Python 3" update, also quite some time ago. It is now renamed to "type" (again) so it matches the Python 3 code it is overriding. * dns.flags.to_text() and dns.flags.edns_to_text() no longer silently drop set bits that have no named flag. Such bits are now rendered as FLAGn, where n is the bit position, and dns.flags.from_text() / edns_from_text() parse that form back, so the conversions round-trip. See issue #1264. * dns.ttl.from_text() now raises dns.ttl.BadTTL, rather than leaking a bare ValueError, when the text contains a non-decimal Unicode "digit" (e.g. the superscript \u00b2). Such characters are accepted by str.isdigit() but rejected by int(), so they previously escaped the parser’s validation. This also makes zone files with such a TTL fail with a clean dns.exception.SyntaxError. * The zone file reader no longer treats a quoted string as a directive. A line starting with "$TTL" was processed as if it were $TTL, because only the token’s value was tested and not its type; a directive must now be an unquoted identifier. This also fixes a crash: a line beginning with an empty token (e.g. an empty quoted string) made the reader raise a bare ... changelog too long, skipping 158 lines ... - The minimum supported version of Python is 3.11. ==== qrca ==== Version update (26.08.1 -> 26.08.2) Subpackages: qrca-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== signon-kwallet-extension ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== skanlite ==== Version update (26.08.1 -> 26.08.2) Subpackages: skanlite-lang - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== vlc ==== Subpackages: libvlc5 libvlccore9 vlc-codec-gstreamer vlc-lang vlc-noX vlc-qt - Require vlc from vlc-devel: whereas the desktop app is not exactly needed when building against the libraries, many consumers expect the full stack to be present. - Drop schroedinger-devel BuildRequires: Not needed, nor used. Upstream removed support in 3.0.24 - Rework subpackaging * Split the desktop output plugins out of the main vlc package, for use on headless systems * Installing vlc-noX and vlc-plugins-desktop will now give a fully functional CLI installation, without pulling in the graphical frontend * Main 'vlc' package will now pull in all components for desktop GUI interface ==== webkitgtk3 ==== Subpackages: WebKitGTK-4.1-lang libjavascriptcoregtk-4_1-0 libwebkit2gtk-4_1-0 typelib-1_0-JavaScriptCore-4_1 typelib-1_0-WebKit2-4_1 webkit2gtk-4_1-injected-bundles - Add 30 gigs of memory constraint for aarch64 and x86_64. ==== webkitgtk4 ==== Subpackages: WebKitGTK-6.0-lang libjavascriptcoregtk-6_0-1 libwebkitgtk-6_0-4 typelib-1_0-JavaScriptCore-6_0 typelib-1_0-WebKit-6_0 webkitgtk-6_0-injected-bundles - Add 30 gigs of memory constraint for aarch64 and x86_64. ==== wireplumber ==== Subpackages: libwireplumber-0_5-0 wireplumber-bash-completion wireplumber-lang wireplumber-zsh-completion - fixup fdupes ==== xorg-x11-server ==== Subpackages: xorg-x11-server-Xvfb xorg-x11-server-extra - 0001-xkb-NULL-text-pointer-after-free-in-_CheckSetDoodad-.patch XKB SetGeometry TextDoodad Double Free (bsc#1281213, CVE-2026-88812, ZDI-CAN-31221) - 0002-xkb-allocate-names-keys-to-MAP_LENGTH-in-XkbAllocNam.patch XKB ChangeKeycodeRange Heap Out-of-Bounds Write (bsc#1281236, CVE-2026-93520, ZDI-CAN-31941) - 0003-xkb-widen-size_syms-num_syms-size_acts-num_acts-to-u.patch XKB ResizeKeyType Numeric Truncation (bsc#1281227, CVE-2026-93518, ZDI-CAN-31834) - 0004-xkb-fix-CheckKeySyms-overwriting-request-range-symsP.patch XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read (bsc#1281242, CVE-2026-93524, ZDI-CAN-32408) - 0005-randr-fix-size-and-offset-in-RRChangeProviderPropert.patch RandR ChangeProviderProperty Heap Buffer Overflow (bsc#1281238, CVE-2026-93521, ZDI-CAN-31944) - 0006-Xi-validate-modifier-values-in-ProcXIPassiveUngrabDe.patch XInput2 PassiveUngrabDevice Out-of-Bounds Write (bsc#1281241, CVE-2026-93523, ZDI-CAN-32366) - 0007-glx-validate-dataBytes-against-cmdlen-in-RenderLarge.patch GLX RenderLarge Heap Buffer Overflow (bsc#1281225, CVE-2026-93517, ZDI-CAN-31833) - 0008-present-unlink-notifies-from-window-list-in-present_.patch X.Org Server Present Extension Use-After-Free (bsc#1281218, CVE-2026-93515, ZDI-CAN-31830) - 0009-dix-remove-passive-grabs-referencing-a-device-on-rem.patch X.Org Server XInput Passive Grab Use-After-Free (bsc#1281220, CVE-2026-93516, ZDI-CAN-31832) - 0010-Xi-add-bounds-check-for-barrier-events-in-input_cons.patch XFixes Pointer Barrier Event List Buffer Overflow (bsc#1281233, CVE-2026-93519, ZDI-CAN-31938) - 0011-Xi-clean-up-gesture-sprite-traces-in-WindowGone.patch GestureBuildSprite Use-After-Free (bsc#1281244 CVE-2026-93536, ZDI-CAN-32753) ==== xwayland ==== - 0001-xkb-NULL-text-pointer-after-free-in-_CheckSetDoodad-.patch XKB SetGeometry TextDoodad Double Free (bsc#1281213, CVE-2026-88812, ZDI-CAN-31221) - 0002-xkb-allocate-names-keys-to-MAP_LENGTH-in-XkbAllocNam.patch XKB ChangeKeycodeRange Heap Out-of-Bounds Write (bsc#1281236, CVE-2026-93520, ZDI-CAN-31941) - 0003-xkb-widen-size_syms-num_syms-size_acts-num_acts-to-u.patch XKB ResizeKeyType Numeric Truncation (bsc#1281227, CVE-2026-93518, ZDI-CAN-31834) - 0004-xkb-fix-CheckKeySyms-overwriting-request-range-symsP.patch XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read (bsc#1281242, CVE-2026-93524, ZDI-CAN-32408) - 0005-randr-fix-size-and-offset-in-RRChangeProviderPropert.patch RandR ChangeProviderProperty Heap Buffer Overflow (bsc#1281238, CVE-2026-93521, ZDI-CAN-31944) - 0006-Xi-validate-modifier-values-in-ProcXIPassiveUngrabDe.patch XInput2 PassiveUngrabDevice Out-of-Bounds Write (bsc#1281241, CVE-2026-93523, ZDI-CAN-32366) - 0007-glx-validate-dataBytes-against-cmdlen-in-RenderLarge.patch GLX RenderLarge Heap Buffer Overflow (bsc#1281225, CVE-2026-93517, ZDI-CAN-31833) - 0008-present-unlink-notifies-from-window-list-in-present_.patch X.Org Server Present Extension Use-After-Free (bsc#1281218, CVE-2026-93515, ZDI-CAN-31830) - 0009-dix-remove-passive-grabs-referencing-a-device-on-rem.patch X.Org Server XInput Passive Grab Use-After-Free (bsc#1281220, CVE-2026-93516, ZDI-CAN-31832) - 0010-Xi-add-bounds-check-for-barrier-events-in-input_cons.patch XFixes Pointer Barrier Event List Buffer Overflow (bsc#1281233, CVE-2026-93519, ZDI-CAN-31938) - 0011-Xi-clean-up-gesture-sprite-traces-in-WindowGone.patch GestureBuildSprite Use-After-Free (bsc#1281244 CVE-2026-93536, ZDI-CAN-32753) - 0012-glamor-size-tmp_bits-buffer-for-source-coordinate-ra.patch Glamor CopyArea Heap Buffer Overflow (bsc#1281240, CVE-2026-93522, ZDI-CAN-32361)